printachecks

Privacy Policy

Last updated September 14, 2026

This page says, specifically, what printachecks.com stores, why, how it is protected, and how to get it deleted. It's written to be read.

What we store

DataWhyHow it's held
Email addressIt is your login and where sign-in codes and receipts goPlain text (we have to send to it)
PasswordSign-inNever stored. We keep a salted scrypt hash, from which the password can't be recovered
Name and address on the check, bank namePrinted on your checksPlain text
Routing and account numbersPrinted in the MICR line of your checksEncrypted with AES-256-GCM. The key is held outside the database and outside our code repository. Only the last four digits are stored in readable form
Check registerYour record of what you printed: number, date, payee, amount, memoPlain text
Credit balance and purchase historyTo know how many checks you can print and to handle refundsPlain text; includes Stripe's session ID for each purchase, not your card
Sign-in codes and sessionsTwo-step sign-inHashed. Codes expire in 10 minutes; sessions in 30 days or when you sign out
IP address and browser typeRate-limiting abuse and, per session, so you can recognise your own sign-insPlain text, tied to sessions and short-lived rate-limit records

What we don't store

Who can see your bank numbers

The full routing and account numbers are decrypted for exactly one purpose: sending them to your signed-in browser so it can draw the MICR line on your check. That happens only after you've entered your password and the emailed code. They do not appear in our logs, in emails, on your account page, or in support tools. The server operator can, in principle, access the encryption key and the database; we don't do so except to run the service or when required by law.

Third parties

We don't sell or rent your information, and we don't share it with anyone else except as required by law.

How long we keep it

Your choices

Security, honestly

Passwords are hashed with scrypt; bank numbers are encrypted with AES-256-GCM under a key kept off the database; every sign-in needs a one-time email code; all traffic is HTTPS; the database lives on a server with its own service account and no public port. No system is unbreakable. If we ever learn of a breach affecting your data we will tell you by email promptly and say plainly what was exposed.

Changes

If this policy changes in a way that matters, we'll update the date above and, for material changes, email account holders.

Contact

Reply to any email we've sent you, or use the contact address on our site.